CVE-2026-16232 – Check Point Quantum Security Management & Security Gateway

CVSS 9.8 CRITICAL Zero Day – Immediate Deployment

“An authentication bypass in the management plane can turn a trusted security platform into an attacker's strongest advantage.”

Check Point has released security updates addressing two Critical and one High severity vulnerabilities affecting Quantum Security Management, Multi-Domain Security Management, and Quantum Security Gateway. The fixes resolve authentication bypass and privilege escalation flaws that could allow attackers to gain administrative control, execute privileged commands, modify security policies, and compromise managed security infrastructure if exposed management servers are improperly configured.

CVE-2026-16232 has a CVSS score of 9.1, Critical severity. CVE-2026-62144 has a CVSS score of 9.1, Critical severity. CVE-2026-62145 has a CVSS score of 7.5, High severity. CVE-2026-16232 is being actively exploited in the wild. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with CVE-2026-62144 or CVE-2026-62145.

Key Details

Affected Product
Checkpoint Multi-domain Security Management
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-287
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.